The Agent Watch
Briefing · Articles · Tools · About EN FR DE ES 中文 IT PT SV FI DA

Daily Briefing

21 August 2026 · 5 stories

🔥 Top story

1

Eight AI agents hack a government: cyberattacks just became an autonomous team job

For the first time, we have public proof that a state-level cyberattack was carried out almost entirely by AI agents, with no human at the keyboard. On August 12, the Israeli company Dream Security published the details of an operation that hit Taiwan for four days, with up to eight AI agents working in parallel, day and night. The toll: 21 government systems mapped, 85 official accounts broken into (thanks in part to a well-known old flaw in a connection token format), over 2,500 personnel files stolen, and a sideways move into a nuclear agency and several energy utilities. The attackers bypassed the models' safety guardrails by tricking them into thinking it was an authorized security test. This is the eighth serious agentic incident in a month, and the first where offensive AI agents have moved from the sandbox to the field. The Taiwanese government confirmed the attack on August 13.

2

Nebius raises $4.3 billion to build the AI factory of the year

On August 19, Nebius — a builder of AI-specialized data centers — announced the second-largest convertible bond issuance in the sector's history: $4.3 billion, at an interest rate below 3%. For context, that's more than ten times the annual budget of a large French research university. What's it for? To install thousands of graphics processors to run AI models, in giant warehouses in Finland and Israel. Nebius has already signed a contract potentially worth up to $27 billion with Meta (Facebook), taken $2 billion from Nvidia, and promises to multiply its spending fivefold this year. The bet: demand for AI compute will keep exploding. The risk: if it weakens, the company won't be able to repay.

3

Binance now lets an AI agent trade crypto for you

Imagine hiring a trading assistant that places orders for you, day and night, without getting tired. That's what Binance, the world's largest crypto platform, launched on August 20: Agent OS. In practice, you can plug ChatGPT, Claude Code, Codex or Cursor directly into your Binance account, so they can check prices, manage a portfolio, execute buy-sell orders — and even receive automated payments. To avoid disasters, the agent works in an isolated sub-account with permissions you can revoke. It's the tenth B2B vendor in less than a week to release its own layer for AI agents — a sign that distribution channels like 'Skills' and other open standards for plugging agents into external services are becoming a real market.

4

Google and Anthropic unify their AI agent protocols under one foundation

On August 19, Google's A2A protocol — which lets two AI agents talk to each other — joined the Agentic AI Foundation, the same Linux Foundation that already hosts Anthropic's MCP protocol and Block's goose. To put it simply: when you want your AI assistant to book a flight and ask another specialized agent to compare prices, those two agents need to speak the same language. A2A handles agent-to-agent conversation, MCP handles agent-to-tool conversation (like a database or a payment service). Both are now under the same neutral governance — so they're more stable, more audited, and harder for any single player to break. Membership went from under 40 to over 250 in eight months.

5

Slack Code: your team can now code with AI agents right inside chat

On August 21, Salesforce launched Slack Code: a native layer inside Slack that lets a team invite an AI agent into a conversation, ask it for a code change, see the diff (the before/after difference), and test the change — all without leaving the chat. Multiple agent vendors are supported (no Salesforce lock-in). The important reminder: keep a human in the loop to validate, and test in a separate environment before pushing to production. It's the eleventh B2B vendor in seven days to publish its agentic layer. At this pace, 'not having an API for agents' is becoming an oddity.

📡 To watch

Cloudflare launches a browser 3 to 7 times lighter for AI agents

On August 6, Cloudflare released Kitesurf, a browser rewritten for AI agents — not for humans. Rust compiled to WebAssembly, running in sealed 'sandboxes', much lighter than Chromium. According to Cloudflare, it uses 3 to 4 times less CPU and 5 to 7 times less memory. The browser already handles 20 agent payment integrations (x402 protocol). To watch: will AI agents, which spend their days clicking, become numerous enough to push classic browsers to the margins?

Higgsfield, the startup that clones humans in video, raises $400 million

On August 17, Higgsfield closed a Series B at a $5.4 billion valuation, led by DST Global and Goldman Sachs. The company has 390 Fortune 500 clients and is used in 238 countries. Its specialty: generating videos of realistic 'characters' from a simple description. If Adobe or Figma buy a competitor like Synthesia, it would unlock the whole consolidation of the AI creative sector.

GLM-5.2 Turbo: a new fast, open-source Chinese model

On August 17, Z.ai (formerly Zhipu) released GLM-5.2 Turbo: a speed-optimized version of its large GLM-5.2 model, freely downloadable under an MIT license. It handles a context of one million tokens (the equivalent of a very thick book in memory). It's the third open-source flagship Chinese model out in five days — while American labs (Mistral, Anthropic, OpenAI, Google) haven't released anything comparable. For European companies that want to host their own AI, it's an increasingly credible option.

The Dream/Taiwan attack could inspire copycats in Europe

If the method documented by Dream Security (eight AI agents orchestrated to map a system and steal data) is applied to European banks, hospitals, or airports, that's a very high-risk scenario. The open-source offensive agents used (Hermes, OpenClaw) aren't covered by the transparency obligations of the European AI Act. Recommendation: push for NIS2 and AI Act Article 50 to explicitly include open-source offensive agents in their scope.

📊 Trend

This week illustrates a turning point: in five days, more than $6 billion was raised by AI infrastructure players — 70% of it by Nebius alone. At the same time, ten B2B vendors outside of 'pure' AI (banks, messaging apps, browsers, crypto platforms) released their own layer to plug AI agents into their services. And the eighth serious agentic incident of the summer has just been documented: a government attack carried out almost entirely by AI agents. Three converging dynamics: (1) infrastructure is becoming the #1 investment field; (2) AI agents are becoming a standard distribution channel, like mobile apps were in the 2010s; (3) the cybersecurity battlefield is shifting from defensive to AI-driven offensive.